Key facts
- Russian state-backed hackers identified as TA488 are exploiting a Microsoft Exchange Server vulnerability.
- The exploit creates network backdoors in unpatched systems.
- Attackers use a 'half-click' method triggered by opening malicious emails.
- The exploit installs advanced malware and steals sensitive information.
- Google is exploring faster, no-restart Chrome updates.
- This Chrome update initiative is driven by an increase in detected software vulnerabilities.
- AI security analysis is partly attributed to the rise in vulnerability detection.
Russian state-backed hackers, identified by the designation TA488, are actively exploiting a critical vulnerability within Microsoft Exchange Server. This exploit allows them to establish unauthorized access and create network backdoors in systems that have not been patched against the flaw. The attackers employ a 'half-click' exploit technique, which means that the compromise is initiated simply by the recipient opening a malicious email. Once executed, this exploit installs advanced malware onto the targeted network and facilitates the theft of sensitive information.
